VYPR

rpm package

opensuse/kernel-source&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweed

Vulnerabilities (2,129)

  • CVE-2019-14814HigSep 20, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.

  • CVE-2019-15031MedSep 13, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then access

  • CVE-2019-15030MedSep 13, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe

  • CVE-2019-16234MedSep 11, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-16232MedSep 11, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-16231MedSep 11, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2019-15902MedSep 4, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" co

  • CVE-2019-15504CriAug 23, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).

  • CVE-2019-15099HigAug 16, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • CVE-2019-15098MedAug 16, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • CVE-2019-11479HigJun 19, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixe

  • CVE-2019-11478MedJun 19, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fi

  • CVE-2019-11477HigJun 19, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel

  • CVE-2019-3846HigJun 3, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.

  • CVE-2019-3882MedApr 24, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a syste

  • CVE-2019-3887MedApr 9, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw t

  • CVE-2019-7222MedMar 21, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

  • CVE-2019-7221HigMar 21, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

  • CVE-2019-8912HigFeb 18, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.

  • CVE-2019-6974HigFeb 15, 2019
    affected < 5.14.6-1.4fixed 5.14.6-1.4

    In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

Page 100 of 107